3 ms·
I’ve recently set up nightly automated pentest for my open-source project. I’m considering starting to publish these reports as proof of security posture. If t
by hardsnow 6mo ago
I’ve recently set up nightly automated pentest for my open-source project. I’m considering starting to publish these reports as proof of security posture.
If the cost of security audit becomes marginal, it would seem reasonable to expect projects to publish results of such audits frequently.
There’s probably a quite hefty backlog of medium- and low-severity issues in existing projects for maintainers to suffer through first though.
- Johnny_Bonk 6mo agoWhat do you use for the pentests? any oss libraries?
- hardsnow 6mo agoThis is a sandbox escape pentest so the only tooling needed is Claude Code and a simple prompt that asks it to follow a workflow: https://github.com/airutorg/airut/blob/main/workflows/sandbox-pentest.md https://github.com/airutorg/airut/blob/main/workflows/sandbo...